how do I register my organisation as a NIS2 obligated entity
Registration occurs through the national supervisory authority, not through this platform
Registration is a separate, formal step: an entity designated as essential or important under the Cybersecurity Act registers itself with the competent supervisory authority via the portal established for that purpose. This happens independently of completing policy documents or implementing measures — it is the administrative step through which an organisation becomes known to the supervisory authority as an obligated entity. The precise procedure, the moment at which this must occur, and what information is required are described on the supervisory authority's own channels and in the Cybersecurity Act.
Before registration becomes relevant, it is useful to first establish whether an organisation falls into that category at all; how do I know if my company falls under NIS2 provides an initial picture of this, and the difference between the two categories that must be registered is explained on what is the difference between an essential entity and an important entity. For those who know that registration is required, the next question is typically practical: what must be in place before registration is submitted, and who within the organisation handles this. This overlaps with setting up the risk management obligations dossier, in which status and responsibility are recorded for each measure — see who should be responsible within my organisation for a measure. This platform prepares the texts and data for registration, but never submits on behalf of the customer to the supervisory authority's portal; that always remains a separate step by the organisation itself.
Why the registration obligation is separate from the risk management obligations
The registration obligation and the risk management obligations are two different obligations that the NIS2 Directive imposes on essential and important entities: Article 21(2) of Directive (EU) 2022/2555 describes the ten measures that together form the risk management obligations, while the reporting obligation and registration are regulated separately and have been implemented in the Netherlands through the Cybersecurity Act. The NCSC provides guidance on how risk management obligations and reporting obligations relate in practice, and the supervisory authority responsible for the relevant sector is the one with whom registration itself takes place.
What this is based on
- Directive (EU) 2022/2555 (NIS2), Article 21(2) — the ten measures
- Cybersecurity Act — the Dutch transposition of NIS2
- ISO/IEC 27001 — Annex A, the control measures
- NCSC — guidance on the security obligation and the reporting obligation
The Regulation itself is available on EUR-Lex. We provide references for each statement; you need not take our word for it.
What you concretely need to do
The breakdown per obligation, including the associated deadlines and templates for documentation, is included in the subscription.
View the subscription First the free NIS2 checkThis is not legal advice. This page provides general information about cybersecurity for SMEs. We do not know your business operations and do not provide sustainability advice, assurance or certification. If you are in doubt about your specific situation, consult an advisor or your accountant.
Written with AI based on the sources above, reviewed by a human on 2026-09-05. Is something incorrect? Let us know — corrections take priority.